Re: About Xen: maybe a reiterative question but ..

Previous message: [thread] [date] [author]
Next message: [thread] [date] [author]
From: L. V. Lammert
Date: Wednesday, October 24, 2007 - 6:31 am

On Wed, 24 Oct 2007, Henning Brauer wrote:

Virtualization provides near absolute security - DOM0 is not visible to
the user at all, only passing network traffic and handling kernel calls.
The security comes about in that each DOMU is totally isolated from the
the others, while the core DOM0 is isolated from any attacks.

There is also a big benefit when maintaing VM images - restoring a VM in
the case of corruption/attach/whatever is as simple as reloading a copy of
that image and connecting to system data on the local SAN.

Irrespective of the guest OS, there is good security between the
virtualized machines. Running OBSD as the guest OS provides the best of
both worlds, and it would be great if OBSD would run paravirtualized for
the best performance, but apparently nobody has a need for that
functionality.

Nobpdy has to write any code to understand that - the secuity benefits
are ovbious to everyone from the PHBs to the admins. Of course, this is
most obvious in 'enterprise space', which is pretty far removed from the
typical OBSD world.

	Lee

================================================
  Leland V. Lammert            lvl@omnitec.net
    Chief Scientist     Omnitec Corporation
 Network/Internet Consultants   www.omnitec.net
================================================
Previous message: [thread] [date] [author]
Next message: [thread] [date] [author]

Messages in current thread:
Re: About Xen: maybe a reiterative question but .., Henning Brauer, (Wed Oct 24, 1:18 am)
Re: About Xen: maybe a reiterative question but .., L. V. Lammert, (Wed Oct 24, 6:31 am)
Re: About Xen: maybe a reiterative question but .., Paul de Weerd, (Wed Oct 24, 7:50 am)
Re: About Xen: maybe a reiterative question but .., Henning Brauer, (Wed Oct 24, 8:12 am)
Re: About Xen: maybe a reiterative question but .., Dave Anderson, (Wed Oct 24, 8:45 am)
Re: About Xen: maybe a reiterative question but .., Adam Getchell, (Wed Oct 24, 9:46 am)
Re: About Xen: maybe a reiterative question but .. , Theo de Raadt, (Wed Oct 24, 9:59 am)
Re: About Xen: maybe a reiterative question but .. , Jack J. Woehr, (Wed Oct 24, 10:14 am)
Re: About Xen: maybe a reiterative question but .., L. V. Lammert, (Wed Oct 24, 10:16 am)
Re: About Xen: maybe a reiterative question but .., Marc Espie, (Wed Oct 24, 10:44 am)
Re: About Xen: maybe a reiterative question but .. , Theo de Raadt, (Wed Oct 24, 10:45 am)
Re: About Xen: maybe a reiterative question but .., L. V. Lammert, (Wed Oct 24, 10:48 am)
Re: About Xen: maybe a reiterative question but .. , Theo de Raadt, (Wed Oct 24, 11:03 am)
Re: About Xen: maybe a reiterative question but .. , L. V. Lammert, (Wed Oct 24, 11:41 am)
Re: About Xen: maybe a reiterative question but .. , Theo de Raadt, (Wed Oct 24, 11:57 am)
Re: About Xen: maybe a reiterative question but .., Paul de Weerd, (Wed Oct 24, 12:22 pm)
Re: About Xen: maybe a reiterative question but .., Darren Spruell, (Wed Oct 24, 12:27 pm)
Re: About Xen: maybe a reiterative question but .. , Theo de Raadt, (Wed Oct 24, 12:46 pm)
Re: About Xen: maybe a reiterative question but .., Henning Brauer, (Wed Oct 24, 1:16 pm)
Re: About Xen: maybe a reiterative question but .., L. V. Lammert, (Wed Oct 24, 1:31 pm)
Re: About Xen: maybe a reiterative question but .., Jason Dixon, (Wed Oct 24, 1:37 pm)
Re: About Xen: maybe a reiterative question but .., L. V. Lammert, (Wed Oct 24, 1:48 pm)
Re: About Xen: maybe a reiterative question but .., Kevin Stam, (Wed Oct 24, 2:04 pm)
Re: About Xen: maybe a reiterative question but .., Daniel Ouellet, (Wed Oct 24, 2:19 pm)
Re: About Xen: maybe a reiterative question but .., Henning Brauer, (Wed Oct 24, 2:26 pm)
Re: About Xen: maybe a reiterative question but .. , Theo de Raadt, (Wed Oct 24, 2:31 pm)
Re: About Xen: maybe a reiterative question but .. , Theo de Raadt, (Wed Oct 24, 2:41 pm)
Re: About Xen: maybe a reiterative question but .. , L. V. Lammert, (Wed Oct 24, 2:59 pm)
Re: About Xen: maybe a reiterative question but .., L. V. Lammert, (Wed Oct 24, 3:00 pm)
Re: About Xen: maybe a reiterative question but .., Henning Brauer, (Wed Oct 24, 3:14 pm)
Re: About Xen: maybe a reiterative question but .. , Tony Abernethy, (Wed Oct 24, 3:27 pm)
Re: About Xen: maybe a reiterative question but .., Matthew Weigel, (Wed Oct 24, 3:35 pm)
Re: About Xen: maybe a reiterative question but .. , L. V. Lammert, (Wed Oct 24, 3:44 pm)
Re: About Xen: maybe a reiterative question but .. , Jack J. Woehr, (Wed Oct 24, 3:52 pm)
Re: About Xen: maybe a reiterative question but .. , Jeremy Huiskamp, (Wed Oct 24, 4:52 pm)
Re: About Xen: maybe a reiterative question but .., Darrin Chandler, (Wed Oct 24, 5:43 pm)
Re: About Xen: maybe a reiterative question but .., L. V. Lammert, (Wed Oct 24, 6:14 pm)
Re: About Xen: maybe a reiterative question but .., L. V. Lammert, (Wed Oct 24, 6:20 pm)
Re: About Xen: maybe a reiterative question but .., L. V. Lammert, (Wed Oct 24, 6:27 pm)
Re: About Xen: maybe a reiterative question but .., Darren Spruell, (Wed Oct 24, 6:46 pm)
Re: About Xen: maybe a reiterative question but .., Steve Shockley, (Wed Oct 24, 6:53 pm)
Re: About Xen: maybe a reiterative question but .., Darrin Chandler, (Wed Oct 24, 6:54 pm)
Re: About Xen: maybe a reiterative question but .., Jason Dixon, (Wed Oct 24, 6:57 pm)
Re: About Xen: maybe a reiterative question but .. , Theo de Raadt, (Wed Oct 24, 7:01 pm)
Re: About Xen: maybe a reiterative question but .., Damien Miller, (Wed Oct 24, 7:01 pm)
Re: About Xen: maybe a reiterative question but .., Damien Miller, (Wed Oct 24, 7:05 pm)
Re: About Xen: maybe a reiterative question but .., Tony Abernethy, (Wed Oct 24, 8:07 pm)
Re: About Xen: maybe a reiterative question but .., Karsten McMinn, (Wed Oct 24, 9:15 pm)
Re: About Xen: maybe a reiterative question but .., Lars Hansson, (Wed Oct 24, 9:50 pm)
Re: About Xen: maybe a reiterative question but .., Lars Noodén, (Wed Oct 24, 11:14 pm)
Re: About Xen: maybe a reiterative question but .., Richard Toohey, (Thu Oct 25, 12:28 am)
Re: About Xen: maybe a reiterative question but .., Richard Toohey, (Thu Oct 25, 12:37 am)
Re: About Xen: maybe a reiterative question but .., Lars Noodén, (Thu Oct 25, 1:00 am)
Re: About Xen: maybe a reiterative question but .., Richard Toohey, (Thu Oct 25, 1:06 am)
Hardware support for secure virtualization (was: About Xen ..., Rodrigo V. Raimundo, (Thu Oct 25, 3:50 am)
Re: About Xen: maybe a reiterative question but .., Douglas A. Tutty, (Thu Oct 25, 6:04 am)
Re: About Xen: maybe a reiterative question but .., Douglas A. Tutty, (Thu Oct 25, 6:16 am)
Re: About Xen: maybe a reiterative question but .., L. V. Lammert, (Thu Oct 25, 7:06 am)
Re: About Xen: maybe a reiterative question but .., Adam Getchell, (Thu Oct 25, 7:30 am)
Re: About Xen: maybe a reiterative question but .., L. V. Lammert, (Thu Oct 25, 8:02 am)
Re: About Xen: maybe a reiterative question but .., L. V. Lammert, (Thu Oct 25, 9:09 am)
Re: About Xen: maybe a reiterative question but .., L. V. Lammert, (Thu Oct 25, 9:11 am)
Re: About Xen: maybe a reiterative question but .., Jason Dixon, (Thu Oct 25, 9:23 am)
Re: About Xen: maybe a reiterative question but .., L. V. Lammert, (Thu Oct 25, 9:26 am)
Re: About Xen: maybe a reiterative question but .., Tom Van Looy, (Thu Oct 25, 9:54 am)
Re: About Xen: maybe a reiterative question but .., L. V. Lammert, (Thu Oct 25, 10:43 am)
Re: About Xen: maybe a reiterative question but .., richardtoohey, (Thu Oct 25, 11:36 am)
Re: About Xen: maybe a reiterative question but .., Subcommander l0r3zz, (Thu Oct 25, 1:36 pm)
Re: About Xen: maybe a reiterative question but .., Matt Rowley, (Fri Oct 26, 5:34 am)
Re: About Xen: maybe a reiterative question but .., Subcommander l0r3zz, (Fri Oct 26, 10:23 am)
Re: About Xen: maybe a reiterative question but .., Shawn K. Quinn, (Sun Oct 28, 11:29 am)
Re: About Xen: maybe a reiterative question but .., Douglas A. Tutty, (Sun Oct 28, 3:18 pm)
Re: About Xen: maybe a reiterative question but .., Nick Holland, (Sun Oct 28, 7:31 pm)
Re: About Xen: maybe a reiterative question but .., Douglas A. Tutty, (Mon Oct 29, 5:43 am)
Re: About Xen: maybe a reiterative question but .., Douglas A. Tutty, (Mon Oct 29, 1:26 pm)